Noetfield ABCP — Penetration / security test scope (public)
Doctrine: v2.8
Origin: https://abcp.noetfield.com
Contact: operations@noetfield.com

HONEST STATUS
- This document is a SCOPE for how ABCP should be tested — not a completed pen-test REPORT.
- We do not publish fabricated findings or fake PDF certificates.
- When an independent test is completed for a contracted environment, the report is shared under NDA via the data room process.

IN SCOPE (agent money control plane)
1. Prompt injection → money tool (create_payment / similar)
2. Confused deputy / cross-tenant write
3. SSRF via tool arguments (invoice URLs, callbacks)
4. Secret echo / credential leakage in tool args or logs
5. Loop / drain against per-tx and daily limits
6. High-value action without confirm
7. Confirm token replay
8. Kill switch / suspend-agent effectiveness
9. Receipt tamper evidence (Ed25519 verify against published key)
10. Authn/authz on live gateway APIs (contracted env only)

OUT OF SCOPE (this public Worker)
- Live money movement (this surface does not move money)
- Social engineering of Noetfield staff
- DoS against third-party model providers
- Testing licensed rail partners without their written authorization

PUBLIC EVIDENCE
- Threat model: https://abcp.noetfield.com/security
- Eval twin: sec.money_v1 (agent-security-bench)
- Receipt schema: https://abcp.noetfield.com/schema/receipt-money-v1.json
- Verify example: POST https://abcp.noetfield.com/v1/receipts/verify

REQUEST FULL REPORT / ENGAGEMENT
Email operations@noetfield.com with subject: ABCP pen-test / NDA data room
